CVE-2024-6298

CRITICAL
Published Jul 5, 2024 Modified Dec 5, 2024 CWE-1287

Description

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely

CVSS v3.1 Score

10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weakness Type (CWE)

CWE-1287 CWE-1287

Affected Products

Vendor Product
abb aspect-ent-12_firmware
abb aspect-ent-12
abb aspect-ent-2_firmware
abb aspect-ent-2
abb aspect-ent-256_firmware
abb aspect-ent-256
abb aspect-ent-96_firmware
abb aspect-ent-96
abb nexus-2128_firmware
abb nexus-2128
abb nexus-2128-a_firmware
abb nexus-2128-a
abb nexus-2128-f_firmware
abb nexus-2128-f
abb nexus-2128-g_firmware
abb nexus-2128-g
abb nexus-264_firmware
abb nexus-264
abb nexus-264-a_firmware
abb nexus-264-a
abb nexus-264-f_firmware
abb nexus-264-f
abb nexus-264-g_firmware
abb nexus-264-g
abb nexus-3-2128_firmware
abb nexus-3-2128
abb nexus-3-264_firmware
abb nexus-3-264
abb matrix-11_firmware
abb matrix-11
abb matrix-216_firmware
abb matrix-216
abb matrix-232_firmware
abb matrix-232
abb matrix-264_firmware
abb matrix-264
abb matrix-296_firmware
abb matrix-296

References

Frequently Asked Questions

What is CVE-2024-6298? +
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely It has a CVSS v3.1 base score of 10.0 (CRITICAL).
How severe is CVE-2024-6298? +
CVE-2024-6298 has a CVSS v3.1 score of 10.0 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2024-6298? +
CVE-2024-6298 affects products from abb, specifically: aspect-ent-12, aspect-ent-12_firmware, aspect-ent-2, aspect-ent-256, aspect-ent-256_firmware, aspect-ent-2_firmware, aspect-ent-96, aspect-ent-96_firmware, matrix-11, matrix-11_firmware, matrix-216, matrix-216_firmware, matrix-232, matrix-232_firmware, matrix-264, matrix-264_firmware, matrix-296, matrix-296_firmware, nexus-2128, nexus-2128-a, nexus-2128-a_firmware, nexus-2128-f, nexus-2128-f_firmware, nexus-2128-g, nexus-2128-g_firmware, nexus-2128_firmware, nexus-264, nexus-264-a, nexus-264-a_firmware, nexus-264-f, nexus-264-f_firmware, nexus-264-g, nexus-264-g_firmware, nexus-264_firmware, nexus-3-2128, nexus-3-2128_firmware, nexus-3-264, nexus-3-264_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-6298? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-6298 — free, no signup required.

Start Free Scan